# Traffic outages may occur because of high utilization of CPU cores that run CoreXL SND instances

Product: CoreXL  
Version: R81.20  
OS: Gaia  
Last Modified: 2025-02-17

## Symptoms

- Random traffic outage through a Security Gateway / Cluster / VSX Virtual System.
- High rate of RX-Drops even though we see low rate of throughput.
- Output of the `top` command on the Security Gateway / Cluster Member during the traffic outage shows very high utilization of CPU cores that run the CoreXL SND instances.
- Output of the `perf top -C` command on the Security Gateway / Cluster Member during the traffic outage shows that the function responsible for the high CPU utilization is `fwmultik_do_seq_on_packet`.

Example:

```
61.11% snd          [kernel.kallsyms] [k] fwmultik_do_seq_on_packet
26.99% ksoftirqd/37 [kernel.kallsyms] [k] fwmultik_do_seq_on_packet
```

- The `$FWDIR/log/fwk.elg` file (in VSX mode) or `/var/log/messages` file (in Gateway mode) on the Security Gateway / Cluster Member contains this line repeatedly:

`fwmultik_do_sequence_accounting_on_entry: sequence xxxxxxxx out of order (last handled sequence 4294967295)`

## Cause

Utilization of CPU cores that run CoreXL SND instances may reach high levels when there are connections with a long duration that transfer large traffic volume.

## Solution

This problem was fixed. The fix is included in:

- [Check Point R82](https://support.checkpoint.com/results/sk/sk181127)
- [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 70

If you choose not to upgrade, Check Point can supply a **Hotfix**. [Contact Check Point Support](https://www.checkpoint.com/support-services/.contact-support/) to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

**Hotfix installation instructions:**

Refer to [sk168597 - How to install a Hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk168597).

This immediate **workaround** is available:

1. Connect to the command line on the Security Gateway / each Cluster Member / Security Group.
2. Log in to the Expert mode.
3. Configure the value of the kernel parameter `fwmultik_validate_sequence` to 0 (zero):

**Note** - This kernel parameter controls whether to print additional information during a kernel debug. It has no effect on the performance or security.

**Important Note - Before you install the hotfix for this issue, permanently configure the value of the kernel parameter `fwmultik_validate_sequence` to 1 (one).**

|     |     |     |
| --- | --- | --- |
| Deployment | Temporary Configuration | Permanent Configuration |
| Security Gateway,<br>ClusterXL | In Gaia Clish, or in the Expert mode:<br>`fw ctl set int fwmultik_validate_sequence 0` | In Gaia Clish, or in the Expert mode:<br>`fw ctl set -f int fwmultik_validate_sequence 0` |
| Security Group in Maestro,<br>Security Group on Scalable Chassis | In Gaia gClish:<br>`fw ctl set int fwmultik_validate_sequence 0`<br>In the Expert mode:<br>`g_fw ctl set int fwmultik_validate_sequence 0` | In Gaia gClish:<br>`fw ctl set -f int fwmultik_validate_sequence 0`<br>In the Expert mode:<br>`g_update_conf_file $FWDIR/modules/fwkern.conf fwmultik_validate_sequence=0` |

#### NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

## Article Properties

Access Level: General  
Status: Approved by TAC  
Date Created: 2024-02-15  
Last Modified: 2025-02-17
